SAML Authentication

Article Number:02034
Intended audience: cybozu.cn Administrators

This page describes how to integrate an existing Identity Provider (IdP) with cybozu.cn using SAML authentication.
When SAML authentication is enabled, users can single sign-on (SSO) into cybozu.cn by using user accounts registered with IdPs such as Microsoft Entra ID and Okta.

IdPs That Can Be Integrated with cybozu.cn

cybozu.cn can be integrated with IdPs that support SAML 2.0.

When SAML authentication is enabled, cybozu.cn acts as a Service Provider (SP) and uses SP-initiated SSO. The following bindings are used for the SAML request and SAML response:

  • SAML request: HTTP Redirect Binding
  • SAML response: HTTP POST Binding

Services That Support SAML Authentication

SAML authentication can be used in all services and license plans in cybozu.cn.
However, kintone guests cannot use SAML authentication.

Steps to Enable SAML Authentication

Configure both the IdP and cybozu.cn by following the steps below.
IdP settings should be configured in advance.

Registering information of cybozu.cn with the IdP
Register the information required to configure cybozu.cn as an SP with the IdP.
STEP 1: Registering cybozu.cn with the IdP
Configuring SAML Authentication for cybozu.cn
On cybozu.cn, enable SAML authentication and set the information of the IdP.
STEP 2: Configuring SAML Authentication for cybozu.cn
Enabling to Use Only SAML Authentication When Logging In
If required, you can configure to use only SAML authentication when logging in to cybozu.cn.
If this setting is enabled, users will not be able to log in to the service using password authentication.
STEP 3: Enabling to Use Only SAML Authentication When Logging In